/*
 * Copyright 2004 - 2013 Wayne Grant
 *           2013 - 2025 Kai Kramer
 *
 * This file is part of KeyStore Explorer.
 *
 * KeyStore Explorer is free software: you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
 *
 * KeyStore Explorer is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with KeyStore Explorer.  If not, see <http://www.gnu.org/licenses/>.
 */
package org.kse.gui.actions;

import java.awt.Toolkit;
import java.io.File;
import java.io.FileNotFoundException;
import java.io.FileOutputStream;
import java.io.IOException;
import java.nio.file.NoSuchFileException;
import java.security.KeyStore;
import java.security.KeyStoreException;
import java.security.PublicKey;
import java.security.cert.X509Certificate;
import java.text.MessageFormat;

import javax.swing.ImageIcon;
import javax.swing.JOptionPane;

import org.kse.crypto.CryptoException;
import org.kse.crypto.publickey.JwkPublicKeyExporter;
import org.kse.crypto.publickey.OpenSslPubUtil;
import org.kse.crypto.x509.X509CertUtil;
import org.kse.gui.KseFrame;
import org.kse.gui.dialogs.importexport.DExportPublicKey;
import org.kse.gui.error.DError;
import org.kse.utilities.history.KeyStoreHistory;

/**
 * Action to export the selected key pair entry's public key.
 */
public class ExportKeyPairPublicKeyAction extends KeyStoreExplorerAction {
    private static final long serialVersionUID = 1L;

    /**
     * Construct action.
     *
     * @param kseFrame KeyStore Explorer frame
     */
    public ExportKeyPairPublicKeyAction(KseFrame kseFrame) {
        super(kseFrame);

        putValue(LONG_DESCRIPTION, res.getString("ExportKeyPairPublicKeyAction.statusbar"));
        putValue(NAME, res.getString("ExportKeyPairPublicKeyAction.text"));
        putValue(SHORT_DESCRIPTION, res.getString("ExportKeyPairPublicKeyAction.tooltip"));
        putValue(SMALL_ICON, new ImageIcon(
                Toolkit.getDefaultToolkit().createImage(getClass().getResource("images/keypairexportpub.png"))));
    }

    /**
     * Do action.
     */
    @Override
    protected void doAction() {
        File exportFile = null;

        try {
            String alias = kseFrame.getSelectedEntryAlias();

            PublicKey publicKey = getPublicKey(alias);

            boolean isKeyExportableAsJWK = JwkPublicKeyExporter.isPublicKeyTypeExportable(publicKey);

            DExportPublicKey dExportPublicKey = new DExportPublicKey(frame, alias, isKeyExportableAsJWK);
            dExportPublicKey.setLocationRelativeTo(frame);
            dExportPublicKey.setVisible(true);

            if (!dExportPublicKey.exportSelected()) {
                return;
            }

            exportFile = dExportPublicKey.getExportFile();

            byte[] encoded = null;

            switch (dExportPublicKey.getSelectedPubKeyFormat()) {
                case OPENSSL_PEM:
                    encoded = OpenSslPubUtil.getPem(publicKey).getBytes();
                    break;
                case OPENSSL:
                    encoded = OpenSslPubUtil.get(publicKey);
                    break;
                case JWK:
                    encoded = JwkPublicKeyExporter.from(publicKey, alias).get();
                    break;
            }

            exportEncodedPublicKey(encoded, exportFile);

            JOptionPane.showMessageDialog(frame, res.getString(
                                                  "ExportKeyPairPublicKeyAction.ExportPublicKeySuccessful.message"),
                                          res.getString("ExportKeyPairPublicKeyAction.ExportPublicKey.Title"),
                                          JOptionPane.INFORMATION_MESSAGE);
        } catch (FileNotFoundException | NoSuchFileException ex) {
            String message = MessageFormat.format(res.getString("ExportKeyPairPublicKeyAction.NoWriteFile.message"),
                                                  exportFile);

            JOptionPane.showMessageDialog(frame, message,
                                          res.getString("ExportKeyPairPublicKeyAction.ExportPublicKey.Title"),
                                          JOptionPane.WARNING_MESSAGE);
        } catch (Exception ex) {
            DError.displayError(frame, ex);
        }
    }

    private PublicKey getPublicKey(String alias) throws CryptoException {
        return X509CertUtil.orderX509CertChain(getCertificateChain(alias))[0].getPublicKey();
    }

    private X509Certificate[] getCertificateChain(String alias) throws CryptoException {
        try {
            KeyStoreHistory history = kseFrame.getActiveKeyStoreHistory();
            KeyStore keyStore = history.getCurrentState().getKeyStore();

            return X509CertUtil.convertCertificates(keyStore.getCertificateChain(alias));
        } catch (KeyStoreException ex) {
            String message = MessageFormat.format(res.getString("ExportKeyPairPublicKeyAction.NoAccessEntry.message"),
                                                  alias);
            throw new CryptoException(message, ex);
        }
    }

    private void exportEncodedPublicKey(byte[] encoded, File exportFile) throws IOException {
        try (FileOutputStream fos = new FileOutputStream(exportFile)) {
            fos.write(encoded);
            fos.flush();
        }
    }
}
